Sub-processors

Last Updated:

Subprocessors, AI Data Use & Data Residency

Feather Financial Inc. ("Feather") uses a limited number of trusted subprocessors to help provide, maintain, and support our AI-based voice and text agents for the lending industry. We are committed to transparency and accountability in how we process data, including disclosing the third parties we work with, how AI models handle data, and where that data is stored and processed.

Jurisdiction and GDPR Applicability

Feather Financial Inc. is a U.S.-based company, and our services are currently offered only within the United States. We do not target, market to, or process personal data of individuals located in the European Union (EU) or European Economic Area (EEA).

As such, the General Data Protection Regulation (GDPR) does not apply to our operations at this time. However, we are committed to strong data protection practices and follow industry standards for privacy, security, and transparency. Should Feather begin offering services to EU-based individuals or organizations in the future, we will revise our data protection policies and this page accordingly.

Current Subprocessors

To ensure the highest level of service and security, Feather partners with subprocessors that have demonstrated robust data protection measures. Below is a list of our current subprocessors, the data each may process, and whether that data is used to train any models.

Subprocessor

Purpose

Data accessed

Location

Used to train models?

Amazon Web Services, Inc.

Cloud infrastructure and hosting

Platform data at rest (recordings, transcripts, logs)

United States

No

Porter Technologies Inc.

Deployment and infrastructure management

Deployment and infrastructure metadata

United States

No

DeploySentinel, Inc. (dba HyperDX)

Logging, observability, and monitoring

Operational logs and telemetry

United States

No

Twilio Inc.

Telephony services and voice calling

Call audio in transit, phone numbers, SMS content

United States

No

OpenAI OpCo, LLC

AI-powered conversation models

Conversation text (transcripts, prompts) and context

United States

No

Deepgram, Inc.

Speech-to-text and voice transcription

Call audio for transcription

United States

No

Eleven Labs Inc.

Voice and call intelligence functionality

Text for synthesis and generated audio

United States

No

LiveKit Inc.

Web and telephony real-time communication

Real-time audio/media streams

United States

No

All customer data processed by Feather and its subprocessors is stored and handled exclusively within the United States.

AI Model Training and Data Use

Feather does not build or train its own foundation models, and we do not use your data, or your customers' and their consumers' data, to train, fine-tune, or improve any AI model. Customer content is used only to provide the contracted service.

We hold enterprise agreements with each of our AI subprocessors and have configured them to exclude customer data from model training:

  • OpenAI provides our conversational AI models. Data submitted through the OpenAI API is not used to train or improve OpenAI's models, and we have not opted into any data-sharing program. API content is retained only briefly for abuse monitoring (up to 30 days) and then deleted.

  • Deepgram provides speech-to-text transcription. We have opted out of Deepgram's Model Improvement Program, so call audio we send is not stored or used for model training.

  • Eleven Labs provides voice synthesis and call intelligence. Under our enterprise configuration, customer content is not used to train Eleven Labs' models, and we use their data-minimization controls for sensitive workflows.

None of our subprocessors use customer or consumer data to build advertising or marketing profiles, and none redistribute that data to other third parties for their own purposes.

Data Security Within Our Platform and AI Models

We apply administrative, technical, and physical safeguards across our platform and the AI components within it:

  • Encryption. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), including call recordings, transcripts, and logs.

  • Access control. Access to customer and consumer data is role-based and limited to authorized personnel under least-privilege principles, and is reviewed periodically.

  • No persistence in models. Because customer data is excluded from training and fine-tuning, no customer or consumer content is retained in any model's weights. AI subprocessors process content transiently to return a result and then delete it per the retention terms above.

  • Retention and deletion. Feather retains recordings, transcripts, and logs only as long as needed to provide the service and meet applicable requirements (90 day), after which they are deleted or de-identified.

  • Monitoring and incident response. We log key events to support quality assurance, dispute resolution, and security, and maintain an incident-response process that allows us to contain issues and notify affected customers.

Data Residency and U.S. Data Sovereignty

All customer and consumer data processed through Feather is stored and processed within the United States.

  • Our cloud infrastructure (Amazon Web Services) is configured to U.S. regions, and our deployment, observability, and telephony subprocessors operate within the United States.

  • Our AI subprocessors process data on U.S.-based infrastructure under our enterprise agreements, including, where applicable, data-residency and zero-retention configurations that keep processing within the United States.

We do not transfer customer or consumer data outside the United States. If this ever changes, we will update this page and notify affected customers in advance.

Third- and Fourth-Party Vendors

We recognize that our customers, and their lender partners, increasingly need visibility into not just the vendors we use, but the vendors our vendors rely on. Each subprocessor listed above maintains its own subprocessors and is selected and contracted to meet our standards for U.S. data residency, confidentiality, and exclusion of customer data from model training. As part of our vendor management process, we assess our subprocessors' compliance posture and require them to uphold these standards across their own supply chain.

Subprocessor Change Notifications

We are committed to notifying our paying customers of any material changes to the subprocessors that may affect how their data is processed. These notifications are sent via email and apply only to changes relevant to the customer's use of Feather services.

Subprocessor Security and Confidentiality Requirements

Each subprocessor Feather engages is required to meet our standards for data protection, confidentiality, and security. We ensure subprocessors:

  • Only access data required to perform their functions;

  • Are contractually bound to maintain the confidentiality and security of data; and

  • Have implemented appropriate technical and organizational measures to protect customer data.

Questions or Concerns?

If you have any questions or concerns about this page or our data practices, please contact us at:

📧 support@featherhq.com

The platform powering humanlike phone calls — at AI speed.

Artificial Intelligence lab with a mission to build the most powerful AI tools for finance industry.

© 2025 Feather Financial Inc. All Rights Reserved.